Atlassian Jira Align Improper Authorization Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability exists in Jira Align versions 11.14.0, 11.14.1, 11.15.0, 11.15.1, and 11.16.0, related to improper authorization. This issue allows a low-privilege user to perform actions by including a state-related parameter from a user with sufficient privileges. The vulnerability could lead to unauthorized actions being executed by users who should not have the necessary rights.

Impact

Exploitation of this vulnerability could allow low-privilege users to perform actions that require higher privileges, potentially leading to unauthorized changes or access within the application.

Remediation

Users can upgrade to Jira Align version 11.16.1 to address this vulnerability.

Added: Oct 22, 2025, 6:29 PM
Updated: Oct 22, 2025, 9:27 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
5.0
exploitability
5.4
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.